How to Handle Client Logins and Passwords as a VA (Without Putting Anyone at Risk) | Virtueasy
Onboarding

How to Handle Client Logins and Passwords as a VA (Without Putting Anyone at Risk)

· Virtueasy · Security & Access · 6 min read

The moment a new client says "I'll just send you the login" is not an admin detail. It is a test you did not know you were sitting.

How you respond in that first week tells the client more about your professionalism than any welcome packet you sent them.

This guide is for the VA who is about to be handed access to a client's accounts and wants to do it right, not just quickly.

Why the Access Conversation Matters More Than You Think

Most clients have never thought carefully about how they share account access. They default to whatever feels fastest, which usually means a password copied into a DM, an email with login credentials in plain text, or a spreadsheet shared via Google Drive with permissions left wide open.

When you push back on that and offer a better way, you do not look difficult. You look like someone who has been here before. That is a significant credibility signal before you have completed a single task.

The Rule That Is Not Negotiable: Never Accept a Password Over DM or Email

Passwords sent through messaging apps or email are exposed at every point along the way. If either party's account is ever compromised, those credentials are sitting right there in a conversation thread or inbox. This is not a hypothetical risk. It is the most common way business accounts get taken over.

If a client tries to share a login this way, the response is simple: "Let's use a more secure method. Here is what I'd suggest." Then give them one of the options below.

This also matters for your own liability. If something goes wrong with a client account and you were handling the login over DM, that context will be part of any dispute.

Use Delegated Access Wherever the Platform Allows It

The cleanest solution is also the most professional one. Most major platforms have a way to give a second user access without sharing the account password at all. Here is what that looks like on the platforms you will encounter most often.

If the platform supports it, delegated access is always the right answer.

Related: Client onboarding for VAs, step by step

When a Shared Login Genuinely Cannot Be Avoided

Some platforms do not support multiple users. Some clients are on legacy tools that predate the concept. In those cases, a password manager is the only acceptable method for handling shared credentials.

Tools like 1Password, Bitwarden, and LastPass all have a shared vault or item-sharing feature. The client creates an entry for the login, shares it with your account via the password manager, and you access it from there. The password itself is never visible in a chat thread or email.

This approach also means that when the client updates the password, the vault updates automatically. You are always working with current credentials and neither of you has to chase the other down.

Encourage clients who are not already using a password manager to set one up before onboarding starts. This is something the Virtueasy onboarding kit covers in the setup checklist.

Related: The VA client onboarding system that makes you look like a pro from day one

Handling Two-Factor Authentication Without Becoming the Bottleneck

Two-factor authentication (2FA) is a layer of security worth keeping in place, but if the 2FA code is sent to the client's phone and you need it to log in, you are now blocked every time you need access.

There are a few ways to handle this without removing the protection entirely. The first is to ask whether the platform supports an authenticator app. Google Authenticator and Authy both allow a QR code to be shared, which means the client can set up the app on their device and you can set it up on yours using the same underlying code. Both generate valid login codes independently.

The second option, available on some platforms, is to add a secondary trusted phone number or email address. This can be a dedicated VA number or email that routes codes to you without removing the client's primary 2FA setup.

What you should never do is ask a client to turn off 2FA just to make your access easier. That conversation should not happen.

What to Put in Your Client Agreement

Secure password management for virtual assistants is not just about tools. It also requires clarity on paper. Your client agreement or a standalone data handling addendum should cover the following.

This does not need to be a lengthy legal document. A clear, plain-language section in your standard contract covers the essentials and signals that you take client data protection seriously.

Related: What to put in your VA contract before you start work

What to Do If You Suspect a Breach

If you notice unusual account activity, a login from an unrecognized location, or anything that suggests credentials may have been compromised, contact the client the same day. Do not wait to see if it resolves. The steps are: flag it immediately, change the affected credentials via the password manager or delegated access settings, review recent account activity, and document what you noticed and when.

Your legal and ethical responsibility as a VA is to handle client information with the same care you would want applied to your own. Most data protection obligations do not disappear because you are a contractor rather than an employee.

Handing Access Back Cleanly When the Contract Ends

Offboarding access is just as important as setting it up. At the end of every contract, go through every platform you had access to and confirm with the client that your access has been revoked. If you were using shared vault entries in a password manager, confirm those have been removed or that the passwords have been changed. If the client added you as a team member anywhere, verify that your seat has been deactivated.

Keep a running list of every platform you were given access to. This is for your protection as much as the client's.

A clean offboarding is what makes a client comfortable referring you. It closes the loop.

The VA who handles access well at the start of a contract is the one who gets asked back. Get this right in week one and it will not come up again.

Ready to build your VA business?

The VA Starter Kit

Step-by-step guidance for landing your first high-ticket client. No experience required.

Get the VA Starter Kit - $27